๐ฉ๐ช
Vegascosmetics
2026-06-17 16:26:08
(1 day ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after suspicious activity. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐จ๐ญ
backslash
2026-06-17 16:12:00
(1 day ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-17 16:01:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherrys ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 12:01:02.685584 2026] [security2:error] [pid 10237:tid 10237] [client 84.32.131.164:30314] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||borzois.com|F|2"] [data ".borzois.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "borzois.com"] [uri "/silkenswift/www.borzois.com"] [unique_id "ajLEvmm-Tq8RbMiVdahtjQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 14:23:48
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherrys ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 10:23:44.764649 2026] [security2:error] [pid 9286:tid 9286] [client 84.32.131.164:15650] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chicagowca.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chicagowca.com"] [uri "/[email protected] "] [unique_id "ajKt8Ae_r9E0BGsS0C-LCgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-17 14:07:18
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-17 13:43:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherrys ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 09:42:58.987844 2026] [security2:error] [pid 26612:tid 26612] [client 84.32.131.164:57680] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||idodat.com|F|2"] [data ".php.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "idodat.com"] [uri "/index.php.OLD"] [unique_id "ajKkYqKBgFtNo5a0mnPFlwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-06-17 12:47:58
(1 day ago)
http-crawl-non_statics - IP: 84.32.131.164 - time="2026-06-17T14:47:57+02:00" level=info msg="(555f ...
show more
http-crawl-non_statics - IP: 84.32.131.164 - time="2026-06-17T14:47:57+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-crawl-non_statics by ip 84.32.131.164 (US/204770) : 4h ban on Ip 84.32.131.164" module=db
show less
Bad Web Bot
Anonymous
2026-06-17 12:12:19
(1 day ago)
Suspicious activity detected in web server access logs
Web App Attack
Anonymous
2026-06-17 11:14:00
(1 day ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 03:06:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherrys ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 23:06:23.007953 2026] [security2:error] [pid 10850:tid 10850] [client 84.32.131.164:10288] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.localpetsitters.com|F|2"] [data ".egahvets.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.localpetsitters.com"] [uri "/about-2/resources/www.egahvets.com"] [unique_id "ajIPL2Ae2Z5aUvM_OhdEDgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-06-17 01:14:07
(1 day ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
Anonymous
2026-06-17 00:41:41
(1 day ago)
Bot / seems abusive / Apache connections: 182
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-06-16 23:20:45
(1 day ago)
*
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-16 21:15:25
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherrys ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.131.164 (ip-84-32-131-164.007.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 17:15:20.179219 2026] [security2:error] [pid 27707:tid 27707] [client 84.32.131.164:2140] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||instituteofscience.com|F|2"] [data ".instituteofscience.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "instituteofscience.com"] [uri "/www.instituteofscience.com"] [unique_id "ajG86MsxIQmErbJKKR68-QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-16 20:50:03
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack